TL;DR: Spreadsheet-based access reviews in manufacturing create the appearance of compliance while stripping out SoD conflict context, lifecycle events, and remediation evidence, according to OpenIAM. The deeper problem is that review cadence, not role names alone, determines whether access governance can actually catch inappropriate entitlements.
NHIMG editorial — based on content published by OpenIAM: Why Spreadsheet Access Reviews Fail Manufacturing Teams
By the numbers:
- When AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes and as quickly as 9 minutes in some cases.
Questions worth separating out
Q: What breaks when user access reviews stay spreadsheet-based?
A: Spreadsheet-based reviews break because they capture a stale snapshot, hide effective permissions, and rely on human follow-up for enforcement.
Q: Why do manufacturing access reviews need lifecycle-triggered campaigns?
A: Manufacturing environments change access through plant transfers, promotions, terminations, and contractor end dates.
Q: How do organisations know whether access reviews are working?
A: Access reviews are working when they lead to timely removals, reduced exception volume, and role definitions that stop accumulating unused rights.
Practitioner guidance
- Replace spreadsheet-only reviews with governed workflow Require every certification campaign to carry reviewer identity, decision state, timestamps, and tracked remediation so the evidence trail is exportable without manual reconstruction.
- Bind reviews to lifecycle triggers Connect mover, leaver, plant transfer, and contractor expiration events to access review initiation so inappropriate access is challenged when the identity changes, not at the next calendar cycle.
- Surface SoD conflict context in every item Show conflict status, role combination risk, and cross-system entitlements directly in the review queue so approvers can see why an access item is risky before they approve it.
What's in the full article
OpenIAM's full article covers the operational detail this post intentionally leaves for the source:
- The spreadsheet review failure modes mapped to SAP, directory, plant, and contractor access.
- The audit evidence model for reviewer decisions, revocations, and exception handling.
- The event-driven access review pattern for joiner, mover, leaver, and contractor changes.
- The manufacturing-specific SoD conflict examples that a role-name-only review will miss.
👉 Read OpenIAM's analysis of why spreadsheet access reviews fail in manufacturing →
Spreadsheet access reviews in manufacturing: where do they fail?
Explore further
Spreadsheet access reviews create evidence without assurance. A completed file proves that items were marked, not that access was understood, challenged, or removed. In manufacturing, where a single user may span SAP, directory groups, and plant systems, that distinction matters because audit confidence depends on control substance, not activity volume. The practical conclusion is that review artefacts must show context and outcome, not just participation.
A few things that frame the scale:
- Only 44% of developers are reported to follow security best practices for secrets management, according to The State of Secrets in AppSec.
- Organisations maintain an average of 6 distinct secrets manager instances, which fragments control and complicates lifecycle governance.
A question worth separating out:
Q: When does a spreadsheet review become a compliance risk?
A: It becomes a risk when approvers cannot see SoD conflicts, cross-system combinations, or contractor expiry status, because then they are signing off on incomplete identity information. That creates false confidence and leaves the organisation unable to show that inappropriate access was identified and removed in a defensible way.
👉 Read our full editorial: Spreadsheet access reviews fail when identity context is stripped